Red Hat released RHSA-2024:3529 for supported RHEL 8.4 service variants, updating the Linux kernel to remediate CVE-2023-52578 and CVE-2024-1086. The advisory applies to Extended Life Cycle Long Life, Advanced Update Support, Telecommunications Update Service, and SAP Solutions update-service deployments on x86_64 and ppc64le.
CVE-2023-52578 is a low-severity race condition in the bridge-networking function br_handle_frame_finish() that can cause unsynchronized network-device statistics updates; upstream resolved it with the SMP-safe DEV_STATS_INC() mechanism. The kernel update also fixes a use-after-free vulnerability in nftables' nft_verdict_init() function (CVE-2024-1086). Organizations should install the updated kernel and reboot affected systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
11 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:3618 and RHSA-2024:3627, providing fixed RHEL 8 kernel and kernel-rt packages, respectively.
Red Hat released RHSA-2024:3530 with fixed kernel-rt packages for the RHEL 8.4 Telecommunications Update Service.
Red Hat issued RHSA-2024:3529 for supported RHEL 8.4 service variants, providing kernel version 4.18.0-305.131.1.el8_4 to remediate CVE-2023-52578 and CVE-2024-1086. Red Hat stated that affected systems must be rebooted after installation for the fixes to take effect.
Red Hat released RHSA-2024:3528 with fixed kernel packages for Red Hat Enterprise Linux 8.2 Advanced Update Support.
Red Hat released RHSA-2024:3462 with fixed kernel packages for Red Hat Enterprise Linux 8.6 Extended Update Support.
Red Hat issued RHSA-2024:3318 for RHEL Server 7.6 Advanced Update Support on x86_64, providing kernel build 3.10.0-957.113.1.el7 to fix CVE-2024-1086, a use-after-free flaw in nf_tables' nft_verdict_init() function. Red Hat instructed administrators to reboot after applying the update.
Red Hat released RHSA-2024:2394, updating RHEL 9 kernel packages to remediate CVE-2023-52578.
Red Hat published the CVE-2023-52578 record for a Linux kernel network bridge race condition. Red Hat rated the issue Low severity with a CVSS v3.1 score of 4.7.
Red Hat released RHSA-2024:3810 with fixed kernel packages for Red Hat Enterprise Linux 8.8 Extended Update Support.
The Linux kernel resolved the bridge-networking race condition by replacing the affected statistics updates with the SMP-safe DEV_STATS_INC() mechanism.
syzbot and the Kernel Concurrency Sanitizer reported a race condition in Linux's bridge br_handle_frame_finish() function, where concurrent CPUs could update shared network-device statistics without synchronization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.